First published: Wed Jul 19 2017(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Teclib GLPI | =0.90.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-7507 is classified as low to medium due to the requirement of an authenticated user to exploit the vulnerability.
To fix CVE-2016-7507, users should upgrade to a newer version of GLPI that addresses this Cross-Site Request Forgery vulnerability.
CVE-2016-7507 affects users of GLPI version 0.90.4, specifically those who are authenticated within the application.
CVE-2016-7507 is a Cross-Site Request Forgery (CSRF) vulnerability.
An attacker exploiting CVE-2016-7507 could potentially create an unauthorized admin account within the GLPI application.